PatchSiren

upcasted CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM upcasted CVE published 2026-10-10

CVE-2026-62035

A vulnerability in the Upcasted <= 3.1.0 WordPress plugin allows for broken access control in AWS S3. This issue has a CVSS score of 6.3 and is classified as MEDIUM severity.